What you need to know
- A 12-year-old vulnerability was discovered in Dell computers and flagged up to the company.
- It's estimated that hundreds of millions of devices have the vulnerability.
- Dell has released a security update to address the vulnerability.
Hundreds of millions of Dell computers could have a vulnerability, according to a security report by SentinelLabs. Five high severity flaws were found in Dell's firmware update driver. These flaws impact Dell laptops, desktops, notebooks, and tablets. SentinelLabs states that hundreds of millions of Dell devices with the vulnerability have been released since 2009. Dell has released a security update to address the vulnerability.
The flaws in the firmware update are all assigned one Common Vulnerabilities and Exposures (CVE) number, but SentinelLabs breaks them down into five flaws:
- CVE-2021-21551: Local Elevation Of Privileges #1 – Memory corruption
- CVE-2021-21551: Local Elevation Of Privileges #2 – Memory corruption
- CVE-2021-21551: Local Elevation Of Privileges #3 – Lack of input validation
- CVE-2021-21551: Local Elevation Of Privileges #4 – Lack of input validation
- CVE-2021-21551: Denial Of Service – Code logic issue
SentinelLabs already has a proof of concept to demonstrate how these issues can affect PCs but is withholding sharing it until June 1, 2021 to give people a chance to update.
The report from SentinelLabs explains the potential impact of the vulnerabilities:
The report adds that an attacker with access to an organization's network can also manage to execute code to gain local elevation of privilege.
Dell released a patch for the vulnerabilities and explains them in great detail in a support document (opens in new tab).
SentinelLabs states that it hasn't seen any indication that the vulnerabilities have been exploited in the wild, but warns that "with hundreds of millions of enterprises and users currently vulnerable, it is inevitable that attackers will seek out those that do not take the appropriate action."
Sean Endicott is the news writer for Windows Central. If it runs Windows, is made by Microsoft, or has anything to do with either, he's on it. Sean's been with Windows Central since 2017 and is also our resident app expert. If you have a news tip or an app to review, hit him up at firstname.lastname@example.org.
Get the best of Windows Central in in your inbox, every day!
Thank you for signing up to Windows Central. You will receive a verification email shortly.
There was a problem. Please refresh the page and try again.